diff options
| author | Florian Westphal <[email protected]> | 2023-11-08 13:18:53 +0100 | 
|---|---|---|
| committer | Pablo Neira Ayuso <[email protected]> | 2023-11-08 16:40:30 +0100 | 
| commit | 80abbe8a8263106fe45a4f293b92b5c74cc9cc8a (patch) | |
| tree | 6bdf5f0986d591be15a3551a0d1769cd11fd9b55 /tools/perf/scripts/python/bin/task-analyzer-record | |
| parent | 7b308feb4fd2d1c06919445c65c8fbf8e9fd1781 (diff) | |
netfilter: nat: fix ipv6 nat redirect with mapped and scoped addresses
The ipv6 redirect target was derived from the ipv4 one, i.e. its
identical to a 'dnat' with the first (primary) address assigned to the
network interface.  The code has been moved around to make it usable
from nf_tables too, but its still the same as it was back when this
was added in 2012.
IPv6, however, has different types of addresses, if the 'wrong' address
comes first the redirection does not work.
In Daniels case, the addresses are:
  inet6 ::ffff:192 ...
  inet6 2a01: ...
... so the function attempts to redirect to the mapped address.
Add more checks before the address is deemed correct:
1. If the packets' daddr is scoped, search for a scoped address too
2. skip tentative addresses
3. skip mapped addresses
Use the first address that appears to match our needs.
Reported-by: Daniel Huhardeaux <[email protected]>
Closes: https://lore.kernel.org/netfilter/[email protected]/
Fixes: 115e23ac78f8 ("netfilter: ip6tables: add REDIRECT target")
Signed-off-by: Florian Westphal <[email protected]>
Signed-off-by: Pablo Neira Ayuso <[email protected]>
Diffstat (limited to 'tools/perf/scripts/python/bin/task-analyzer-record')
0 files changed, 0 insertions, 0 deletions